<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Auto reconnect after failure possible?]]></title><description><![CDATA[<p dir="auto">We recently deployed 2 identical pfSense routers at both sites. I configured an IPSec connection between the two that has been rock solid.</p>
<p dir="auto">However, if the connection goes out at either side, I always have to manually reconnect. This sometimes happens if there is a power or internet outage. We would like for this to automatically reconnect.</p>
<p dir="auto">I have DPD enabled, and I have entered a host to ping on the other side. I was under the impression this would cause it to automatically reconnect when dropped, but it doesn't work.</p>
<p dir="auto">Any tips?</p>
]]></description><link>https://forum.netgate.com/topic/106336/auto-reconnect-after-failure-possible</link><generator>RSS for Node</generator><lastBuildDate>Sat, 13 Jun 2026 15:29:11 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/106336.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 07 Oct 2016 16:17:27 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Auto reconnect after failure possible? on Mon, 10 Oct 2016 17:46:47 GMT]]></title><description><![CDATA[<p dir="auto">"Responder only" would do exactly as you described – When the VPN times out or the keys expire, it will not automatically establish again. Unset that on both sides.</p>
]]></description><link>https://forum.netgate.com/post/654332</link><guid isPermaLink="true">https://forum.netgate.com/post/654332</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Mon, 10 Oct 2016 17:46:47 GMT</pubDate></item><item><title><![CDATA[Reply to Auto reconnect after failure possible? on Mon, 10 Oct 2016 17:32:05 GMT]]></title><description><![CDATA[<ul>
<li>Both sides have a static IP, so that isn't changing.</li>
<li>By manually reconnect, I mean go to Status -&gt; IPsec and click on the green button that says "Connect." (When the VPN is up it is red and says "Disconnect")</li>
<li>As I wrote down the settings, I realized I have "Responder only" checked. I have a feeling that is the issue, so I'll uncheck that and test, unless you see any other issues in the configuration.</li>
</ul>
<p dir="auto"><strong># Phase 1</strong></p>
<h2><a class="anchor-offset" name="general"></a>General</h2>
<ul>
<li>Key Exchange version - V2</li>
<li>IPV4</li>
<li>Int: WAN</li>
<li>Remote Gateway: static IP of other site</li>
</ul>
<h2><a class="anchor-offset" name="phase-1-auth"></a>Phase 1 - Auth</h2>
<ul>
<li>Auth Method: Mutual PSK</li>
<li>My Id: My IP Address</li>
<li>Peer Id: Peer IP Address</li>
<li>Pre-Shared Key: same key on both sides</li>
</ul>
<h2><a class="anchor-offset" name="phase-1-algorithms"></a>Phase 1 - Algorithms</h2>
<ul>
<li>Encryption Algorithm: AES256-GCM  - 128 bits</li>
<li>Hash Algorithm: SHA512</li>
<li>DH Group: 24(2048(sub 256) bit)</li>
<li>Lifetime: 86400</li>
</ul>
<h2><a class="anchor-offset" name="advanced-options"></a>Advanced Options</h2>
<ul>
<li>Disable rekey: unchecked</li>
<li>Disable Reauth: unchecked</li>
<li>Responder Only: checked</li>
<li>MOBIKE: Disable</li>
<li>Split Connections: unchecked</li>
<li>DPD: checked</li>
<li>Delay: 10</li>
<li>Max failures: 10</li>
</ul>
<h1><a class="anchor-offset" name="phase-2"></a>Phase 2</h1>
<h2><a class="anchor-offset" name="general"></a>General</h2>
<ul>
<li>Mode: Tunnel IPv4</li>
<li>Local Network: ~~</li>
<li>NAT/BINAT translation: None</li>
<li>Remote Network: ~~</li>
</ul>
<p dir="auto"><strong>## Phase 2</strong></p>
<ul>
<li>Protocol: ESP</li>
<li>Encryption Algorithms: AES256-GCM - 128bits</li>
<li>Hash Algorithms: SHA512</li>
<li>PFS key group: 16(4096 bit)</li>
<li>Lifetime: 3600</li>
</ul>
<h2><a class="anchor-offset" name="advanced-configuration"></a>Advanced Configuration</h2>
<ul>
<li>Automatically ping host:</li>
</ul>
]]></description><link>https://forum.netgate.com/post/654331</link><guid isPermaLink="true">https://forum.netgate.com/post/654331</guid><dc:creator><![CDATA[jasonh]]></dc:creator><pubDate>Mon, 10 Oct 2016 17:32:05 GMT</pubDate></item><item><title><![CDATA[Reply to Auto reconnect after failure possible? on Mon, 10 Oct 2016 14:32:38 GMT]]></title><description><![CDATA[<p dir="auto">It should automatically reconnect in that case. Is the IP address on either side changing? What do you have to do to "manually" reconnect?</p>
<p dir="auto">What are your tunnel settings for both sides? (you can leave out anything sensitive such as keys/exact IP addresses)</p>
]]></description><link>https://forum.netgate.com/post/654297</link><guid isPermaLink="true">https://forum.netgate.com/post/654297</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Mon, 10 Oct 2016 14:32:38 GMT</pubDate></item></channel></rss>